Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Roaming profiles & laptop issues?

Status
Not open for further replies.

pinkpanther56

Technical User
Jun 15, 2005
807
GB
I know this isn't strictly an enterprise issue but i figured this is the forum for questions on mass management and as the XP forum couldn't help i've turned to you.

We are a high school with approx 100 teaching staff, at present about 50 of them have laptops that were provided by the government last year. At the time our department was unable to support these so they we’re handed out as stand alone machines and the owners given administrator access (they do not connect to our network).
This year another 50 laptops will be awarded and they will be handed out, this time however the pressure is on to allow them to connect to the school network so staff can use the internet and collect work from their shared drives.

I would like some advice on how to proceed with a couple of problems I can see emerging.


Staff that already have administrator access to their laptops are reluctant to lose it, they are sent training programs and materials that require installing occasionally and this requires this level of access. I am thinking about insisting that they bring in their laptops so we can install XP SP2 and update their anti virus software, then using WSUS to keep them up to date in future. I am still a bit wary about security issues here so any advice is appreciated.

Next prob:

At present each user has a network account with a roaming profile and a standard desktop that is the same for all staff, how can I prevent this desktop being applied when they log onto the network from their laptop to access their work folders? I was hoping that their network user credentials could be cached on the XP laptop so they can logon using their network user account even when not connected to the network, can this be achieved without any policies been applied to the user on the laptop (policy loopback maybe?)
Alternatively would it be better for them to logon locally to the laptop then give them a shortcut that they can click when plugged into the network that requires they enter their username and password to connect to their work area?

I would like to insist that they all have standard user accounts and admin rights are restricted to our department but this is unlikely to happen, how do people in the forums manage their mobile users and their laptops?

We use Windows 2003 servers with Active Directory and all Laptops are Windows XP.

Thanks for all suggestions.
 
there was no roaming profile set on the network, which is why this is baffling me.(i didnt set a profile location in his ad user account), and i made sure that in "profiles" under my computer properties advanced tab, that his profile was set to local. I will have him login as local admin and change that setting tomorrow, any other ideas to try? i really hope his credentials are still cached.
 
Regarding rights - reduce them to power user, and use "Restricted Groups" feature of Group Policy to load only your Admins groups into the local Admins group of each computer.

Install SP2, then use group policy to mnage the firewall settings.

Good call on WSUS. It works well. If you don't install on a set schedule, then publish each fix with a deadline.

Place all laptops in one Org Unit, and all Desktops in another. Create another Group Policy on the Laptop Org unit that denies Roaming Profiles.

Yes, they can log into the domain when the laptop is not connected to the network. The cached profile is used.

D
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top